Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-1080


LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.


Published

2025-03-04T20:15:36.867

Last Modified

2025-12-10T18:26:24.293

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application libreoffice libreoffice < 24.8.5.1 Yes
Application libreoffice libreoffice < 25.2.1.1 Yes
Operating System debian debian_linux 11.0 Yes

References